| Summary: | Wrong Red Hat signature on the qxl-win driver? | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8 | Reporter: | Christophe Fergeau <cfergeau> |
| Component: | spice-qxl-xddm | Assignee: | Default Assignee for SPICE Bugs <rh-spice-bugs> |
| Status: | CLOSED ERRATA | QA Contact: | Desktop QE <desktop-qa-list> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | --- | CC: | acathrow, cfergeau, cpelland, dblechte, djasa, lveyde, pvine, uril, yeylon |
| Target Milestone: | rc | ||
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | qxl-win-unsigned-0.1-20 qxl-win-0.1-21 | Doc Type: | Bug Fix |
| Doc Text: |
There was a wrong Red Hat signature on the qxl and virtio drivers for Windows, which has now been fixed.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2014-01-21 14:48:58 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
|
Description
Christophe Fergeau
2013-10-07 14:48:28 UTC
This is now fixed in git. Works in qxl-win-0.1-21:
c:\Users\djasa\Desktop>signtool verify /kp /v /c w7\amd64\qxl.cat w7\amd64\qxl.sys
Verifying: w7\amd64\qxl.sys
File is signed in catalog: w7\amd64\qxl.cat
Hash of file (sha1): 590C6E1967DE33AFB17ECDFA910608D34560AE5A
Signing Certificate Chain:
Issued to: Microsoft Root Certificate Authority
Issued by: Microsoft Root Certificate Authority
Expires: Sun May 09 23:28:13 2021
SHA1 hash: CDD4EEAE6000AC7F40C3802C171E30148030C072
Issued to: Microsoft Windows Hardware Compatibility PCA
Issued by: Microsoft Root Certificate Authority
Expires: Thu Jun 04 21:15:46 2020
SHA1 hash: 8D42419D8B21E5CF9C3204D0060B19312B96EB78
Issued to: Microsoft Windows Hardware Compatibility Publisher
Issued by: Microsoft Windows Hardware Compatibility PCA
Expires: Sat Aug 16 18:48:57 2014
SHA1 hash: 3D5C7917B3EE3E4226A471C6BE41196B87594403
The signature is timestamped: Fri Aug 09 18:37:09 2013
Timestamp Verified by:
Issued to: Microsoft Root Certificate Authority
Issued by: Microsoft Root Certificate Authority
Expires: Sun May 09 23:28:13 2021
SHA1 hash: CDD4EEAE6000AC7F40C3802C171E30148030C072
Issued to: Microsoft Time-Stamp PCA
Issued by: Microsoft Root Certificate Authority
Expires: Sat Apr 03 13:03:09 2021
SHA1 hash: 375FCB825C3DC3752A02E34EB70993B4997191EF
Issued to: Microsoft Time-Stamp Service
Issued by: Microsoft Time-Stamp PCA
Expires: Fri Jun 27 20:08:28 2014
SHA1 hash: E0AF7E3AFD2CC3F6E7C72F707A63FA9F9DB511D6
Cross Certificate Chain:
Issued to: Microsoft Root Certificate Authority
Issued by: Microsoft Root Certificate Authority
Expires: Sun May 09 23:28:13 2021
SHA1 hash: CDD4EEAE6000AC7F40C3802C171E30148030C072
Issued to: Microsoft Windows Hardware Compatibility PCA
Issued by: Microsoft Root Certificate Authority
Expires: Thu Jun 04 21:15:46 2020
SHA1 hash: 8D42419D8B21E5CF9C3204D0060B19312B96EB78
Issued to: Microsoft Windows Hardware Compatibility Publisher
Issued by: Microsoft Windows Hardware Compatibility PCA
Expires: Sat Aug 16 18:48:57 2014
SHA1 hash: 3D5C7917B3EE3E4226A471C6BE41196B87594403
Successfully verified: w7\amd64\qxl.sys
Number of files successfully Verified: 1
Number of warnings: 0
Number of errors: 0
c:\Users\djasa\Desktop>signtool verify /kp /v /c w7\x86\qxl.cat w7\x86\qxl.sys
Verifying: w7\x86\qxl.sys
File is signed in catalog: w7\x86\qxl.cat
Hash of file (sha1): 0E57DEBD9B6D01853682DC6D1A287DD55E601468
Signing Certificate Chain:
Issued to: Microsoft Root Certificate Authority
Issued by: Microsoft Root Certificate Authority
Expires: Sun May 09 23:28:13 2021
SHA1 hash: CDD4EEAE6000AC7F40C3802C171E30148030C072
Issued to: Microsoft Windows Hardware Compatibility PCA
Issued by: Microsoft Root Certificate Authority
Expires: Thu Jun 04 21:15:46 2020
SHA1 hash: 8D42419D8B21E5CF9C3204D0060B19312B96EB78
Issued to: Microsoft Windows Hardware Compatibility Publisher
Issued by: Microsoft Windows Hardware Compatibility PCA
Expires: Sat Aug 16 18:48:57 2014
SHA1 hash: 3D5C7917B3EE3E4226A471C6BE41196B87594403
The signature is timestamped: Fri Aug 09 18:37:09 2013
Timestamp Verified by:
Issued to: Microsoft Root Certificate Authority
Issued by: Microsoft Root Certificate Authority
Expires: Sun May 09 23:28:13 2021
SHA1 hash: CDD4EEAE6000AC7F40C3802C171E30148030C072
Issued to: Microsoft Time-Stamp PCA
Issued by: Microsoft Root Certificate Authority
Expires: Sat Apr 03 13:03:09 2021
SHA1 hash: 375FCB825C3DC3752A02E34EB70993B4997191EF
Issued to: Microsoft Time-Stamp Service
Issued by: Microsoft Time-Stamp PCA
Expires: Fri Jun 27 20:08:28 2014
SHA1 hash: E0AF7E3AFD2CC3F6E7C72F707A63FA9F9DB511D6
Cross Certificate Chain:
Issued to: Microsoft Root Certificate Authority
Issued by: Microsoft Root Certificate Authority
Expires: Sun May 09 23:28:13 2021
SHA1 hash: CDD4EEAE6000AC7F40C3802C171E30148030C072
Issued to: Microsoft Windows Hardware Compatibility PCA
Issued by: Microsoft Root Certificate Authority
Expires: Thu Jun 04 21:15:46 2020
SHA1 hash: 8D42419D8B21E5CF9C3204D0060B19312B96EB78
Issued to: Microsoft Windows Hardware Compatibility Publisher
Issued by: Microsoft Windows Hardware Compatibility PCA
Expires: Sat Aug 16 18:48:57 2014
SHA1 hash: 3D5C7917B3EE3E4226A471C6BE41196B87594403
Successfully verified: w7\x86\qxl.sys
Number of files successfully Verified: 1
Number of warnings: 0
Number of errors: 0
c:\Users\djasa\Desktop>signtool verify /kp /v /c xp\x86\qxl.cat xp\x86\qxl.sys
Verifying: xp\x86\qxl.sys
File is signed in catalog: xp\x86\qxl.cat
Hash of file (sha1): 7A023269D2248D454E151C6464C535568DDDC580
Signing Certificate Chain:
Issued to: Microsoft Root Certificate Authority
Issued by: Microsoft Root Certificate Authority
Expires: Sun May 09 23:28:13 2021
SHA1 hash: CDD4EEAE6000AC7F40C3802C171E30148030C072
Issued to: Microsoft Windows Hardware Compatibility PCA
Issued by: Microsoft Root Certificate Authority
Expires: Thu Jun 04 21:15:46 2020
SHA1 hash: 8D42419D8B21E5CF9C3204D0060B19312B96EB78
Issued to: Microsoft Windows Hardware Compatibility Publisher
Issued by: Microsoft Windows Hardware Compatibility PCA
Expires: Sat Aug 16 18:48:57 2014
SHA1 hash: 3D5C7917B3EE3E4226A471C6BE41196B87594403
The signature is timestamped: Fri Aug 09 18:37:09 2013
Timestamp Verified by:
Issued to: Microsoft Root Certificate Authority
Issued by: Microsoft Root Certificate Authority
Expires: Sun May 09 23:28:13 2021
SHA1 hash: CDD4EEAE6000AC7F40C3802C171E30148030C072
Issued to: Microsoft Time-Stamp PCA
Issued by: Microsoft Root Certificate Authority
Expires: Sat Apr 03 13:03:09 2021
SHA1 hash: 375FCB825C3DC3752A02E34EB70993B4997191EF
Issued to: Microsoft Time-Stamp Service
Issued by: Microsoft Time-Stamp PCA
Expires: Fri Jun 27 20:08:28 2014
SHA1 hash: E0AF7E3AFD2CC3F6E7C72F707A63FA9F9DB511D6
Cross Certificate Chain:
Issued to: Microsoft Root Certificate Authority
Issued by: Microsoft Root Certificate Authority
Expires: Sun May 09 23:28:13 2021
SHA1 hash: CDD4EEAE6000AC7F40C3802C171E30148030C072
Issued to: Microsoft Windows Hardware Compatibility PCA
Issued by: Microsoft Root Certificate Authority
Expires: Thu Jun 04 21:15:46 2020
SHA1 hash: 8D42419D8B21E5CF9C3204D0060B19312B96EB78
Issued to: Microsoft Windows Hardware Compatibility Publisher
Issued by: Microsoft Windows Hardware Compatibility PCA
Expires: Sat Aug 16 18:48:57 2014
SHA1 hash: 3D5C7917B3EE3E4226A471C6BE41196B87594403
Successfully verified: xp\x86\qxl.sys
Number of files successfully Verified: 1
Number of warnings: 0
Number of errors: 0
IIUC this bug does not concert RHEV product (as it never shipped non-WHQL drivers) so shouldn't we rather close this as CURRENTRELEASE? The way I understand things is that the WHQL signature is an additional MS signature on top of the Red Hat signatures we set on the driver. One of these Red Hat sigs happened to be wrong/missing, but the WHQL signature takes precedence, so the wrong signature is not really an issue with WHQL drivers. Not sure what difference it makes on non-WHQL drivers, maybe not much of a change either. So this bug is more about correctness/cleanliness rather than fixing an observable issue. I'm fine with any resolution status for this bug. (In reply to Christophe Fergeau from comment #6) > ... > Not sure what difference it makes on non-WHQL drivers, maybe not > much of a change either. Exactly the opposite: the driver with wrong signing can not be used unless you enable testsigning mode (which you should not do unless you're developing a driver). The driver with the fix works just fine after you confirm trust to RH-signed code. (In reply to David Jaša from comment #5) > IIUC this bug does not concert RHEV product (as it never shipped non-WHQL > drivers) so shouldn't we rather close this as CURRENTRELEASE? Yes, RHEV is shipped only with WHQL'd drivers. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. http://rhn.redhat.com/errata/RHEA-2014-0053.html |